Telegram malware scams have risen 2000% in the last 2 months: Scam Sniffer

Source Cryptopolitan

Web3 anti-scam platform ScamSniffer has reported a sizable increase in malware scams on Telegram’s social messaging platform. According to the firm, Telegram group malware scams increased by 2000% between November 2024 and January 2025.

This new form of attack started gaining prominence in late 2024 and continues to grow alarmingly. With this tactic, bad actors use fake groups and verification bots to distribute malware that can access users’ devices and steal their assets.

Telegram Groups malware
Telegram malware groups are increasing rapidly. Source: Scam Sniffer

These fraudulent groups, usually advertised as exclusive alpha, airdrop, or trading groups, lure users to execute malicious code or install fake verification software to join the channel. Once executed, these codes and software allow the bad actors full access to users’ devices, where they can collect sensitive information to steal users’ assets.

Scam Sniffer wrote:

“Once you execute their code or install their “verification” software, they can access your passwords, scan for wallet files, monitor your clipboard, and steal browser data.”

While it is hard to determine how much has been lost to this new attack vector, Scam Sniffer noted the increase in the number of such scams, which suggests that it is working.

Malware attacks come in multiple variants 

Telegram malware scams have several variants that muddle up the waters for users. In one variant, the attackers ask users to input their phone number and login code for verification instead of executing any code or installing software. However, the phone number and login code give them access to the users’ Telegram accounts and allow them to take control.

Beyond using Telegram, the attackers also execute the same tactic using fake Cloudflare verification pages that deploy malicious code to the clipboard. The fake page usually contains a prompt asking for extra verification and requesting a user to run the Windows + R command. If successful, the malware becomes part of the device and is added to Windows startups.

With these bad actors using several variants of the same scam, security experts have called on users to be more cautious about what links they click and the software they install. Scam Sniffer noted that most of this malware usually contains invites promising users they do not need to sign anything or connect their wallet, while some also ask users to join groups for real-time updates.

The firm identified some fake bots that scammers use, including OfficialSafeguardRobot,  SafeguardsAuthenticationBot, and safeguardoff_bot. All these bots have naming similarities with real verification bots, with subtle misspellings and changes to mislead users.

Given that the full scope and impact of these new scam tactics remain unknown, experts noted that the best protection is for users to never run an unknown command, install unverified software, or use clip-based verification. As Scam Sniffer observed, no genuine crypto project requires users to run a code before they can join a group.

Shift to Telegram malware due to users’ awareness of phishing 

Scam Sniffer claims that bad actors adopted these new tactics because users are now more aware of traditional phishing tactics. Although phishing continues to result in significant losses, with almost $500 million lost in 2024, the security firm noted that regular phishing incidents have remained stable over the past two months.

Beyond their novelty, Telegram malware scams have a more devastating impact. This malware gives attackers more access to users’ devices, enabling them to hack multiple wallets and wreak more havoc using the sensitive information they glean from victims’ devices.

Interestingly, hackers are not just impersonating crypto influencers to market their fake groups. They are also using fake pages of legitimate crypto projects to target communities and invite them to join groups. Scam Sniffer identified invites for fake Telegram Groups attributed to projects such as Scoutly, Fridon AI, Build, and Hiero.

From Zero to Web3 Pro: Your 90-Day Career Launch Plan

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Dollar holds above 100 near a 3-month high — three Fed speakers and a $69 billion auction land tonightThe dollar index closed at 100.43 on Monday, its highest close since late July, after a weekly gain of about 1% — the best in more than three months — and is holding above the 100.00 handle in Asia. Three Fed officials speak tonight alongside a $69 billion two-year note auction, the first leg of $183 billion of Treasury supply this week.
Author  Suzie
Sep 22, Tue
The dollar index closed at 100.43 on Monday, its highest close since late July, after a weekly gain of about 1% — the best in more than three months — and is holding above the 100.00 handle in Asia. Three Fed officials speak tonight alongside a $69 billion two-year note auction, the first leg of $183 billion of Treasury supply this week.
placeholder
October hike odds climb toward 60% as Goldman and BofA both flip — what Warsh's "dose of accommodation" really changedRate futures now price roughly 55% to 62% for a 25bp hike at the October 27-28 FOMC, up from about 30% before Chair Warsh's post-meeting framing that the Fed is merely "removing some accommodation." Goldman Sachs has added an October hike to its forecast and Bank of America now sees moves in both October and December. Here is the repricing, the language behind it, and the two data points that decide it.
Author  Irene Q.
Sep 23, Wed
Rate futures now price roughly 55% to 62% for a 25bp hike at the October 27-28 FOMC, up from about 30% before Chair Warsh's post-meeting framing that the Fed is merely "removing some accommodation." Goldman Sachs has added an October hike to its forecast and Bank of America now sees moves in both October and December. Here is the repricing, the language behind it, and the two data points that decide it.
placeholder
Memory chips surge, Nasdaq notches a second straight record close — why the Dow fell 185 points anywayMicron gained 5%, SanDisk 6.8%, Seagate 4% and Western Digital 3% as the memory complex led the Nasdaq Composite to a second consecutive record close of 27,244.28. But the Dow fell 185 points as JPMorgan, Wells Fargo and Schwab slid more than 3% each — a split tape that says more about positioning than about the economy.
Author  Irene Q.
Sep 23, Wed
Micron gained 5%, SanDisk 6.8%, Seagate 4% and Western Digital 3% as the memory complex led the Nasdaq Composite to a second consecutive record close of 27,244.28. But the Dow fell 185 points as JPMorgan, Wells Fargo and Schwab slid more than 3% each — a split tape that says more about positioning than about the economy.
placeholder
US input costs rose at the fastest pace in four years — the September flash PMI beat is an inflation story, not a growth storyUS September flash PMIs came in far above expectations, with the composite at 58.4, a five-year high. But the detail that moved markets was input cost inflation at its fastest since October 2022, driven by fuel, transport and supply shortages. Brent is back above $100 and the 10-year Treasury yield has hit its highest since 2007.
Author  Suzie
Sep 24, Thu
US September flash PMIs came in far above expectations, with the composite at 58.4, a five-year high. But the detail that moved markets was input cost inflation at its fastest since October 2022, driven by fuel, transport and supply shortages. Brent is back above $100 and the 10-year Treasury yield has hit its highest since 2007.
placeholder
Gold Price Forecast: Gold Drops Below $4,300, Will It Continue to Fall? As of the European session on September 24, gold prices (XAUUSD) extended their correction, dipping below $4,300 intraday to hit a low of $4,262.45. After previously rebounding close to $
Author  TradingKey
Sep 24, Thu
As of the European session on September 24, gold prices (XAUUSD) extended their correction, dipping below $4,300 intraday to hit a low of $4,262.45. After previously rebounding close to $
goTop
quote